Skip to content

Security at Satchel

We only claim what we can back up.

Here is what is in place today, and what we confirm with you before a pilot handles sensitive documents or regulated data.

Encrypted transport

Application traffic is transmitted over encrypted HTTPS connections. Before a pilot involving sensitive documents, we confirm the storage and retention approach for that deployment.

Least-privilege access

Access to customer data is restricted to the personnel who need it to deliver the service, with role-based controls.

Decision history

Uploads, manual verification events, record edits, and staffing actions are timestamped to help your team explain what happened and when.

HIPAA scope & safeguards

HIPAA applicability depends on the customer relationship and the data involved. If Satchel will create, receive, maintain, or transmit PHI as a business associate, the required BAA and applicable safeguards must be in place before that PHI is processed.

Pilot-ready controls

Tenant isolation, role-based permissions, signed sessions, and authentication rate limits are built into the application. Enterprise requirements are scoped before rollout.

Responsible disclosure

Found a vulnerability? Email hello@satchelhub.com and we will respond promptly. We appreciate coordinated disclosure.

Security requirements, reviewed before rollout

Satchel does not claim certifications, regulatory guarantees, customer counts, or uptime statistics that have not been independently established. We document your data flow, storage, retention, access, vendor, and BAA requirements before a regulated pilot.

Review security with us